> If I substitute "AI" with "a system that Google's information", you get the same result
No, there are some huge differences:
1. A poisoned LLM can conceal the problem, by acting as expected 99% of the time and then switching to malice depending on surrounding story-context. In contrast, a falsehood in an indexed web page is static and auditable.
2. You can't reliably remove LLM poison once it's in, short of expensively training from scratch. A bad web page is much more easily de-indexed.
3. It's not injecting a false line-item result, it's injecting behavior. Imagine if mentioning "Blackbeard" caused classic Google Search to start talking like a pirate and suggesting ways to murder people. Would Google just wave that away as "users should be skeptical of our product"?
4. These can infect descendant models that use the same weights, for a kind of supply chain attack. In contrast, reusing search-engine code for your own database is probably not going to spit up bad data from web pages on the overall internet.
____
To get an idea of the shape of the threat model... Imagine Google search, except to work it must allow all webpages to permanently append arbitrary obfuscated javascript to its homepage.
And so far we're only looking at the least scary version, where a human is directly interacting with the LLM['s fictional character] and acting as a direct filter. Much worse would be an LLM somewhere with the job of summarizing text reports down to a number, and it fraudulently converts "John Doe is a model inmate and really shouldn't be here" into parole_viability=0.001.